Input validation error in Linux kernel - CVE-2025-71072

 

Input validation error in Linux kernel - CVE-2025-71072

Published: January 14, 2026


Vulnerability identifier: #VU121441
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-71072
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the shmem_rename2() function in mm/shmem.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
python3-perf-debuginfo
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
kernel-source
kernel-extra-modules
linux (Ubuntu package)
linux-aws-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-xilinx (Ubuntu package)
linux-oracle (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-lowlatency (Ubuntu package)
linux-gcp-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-realtime (Ubuntu package)
kernel (Red Hat package)
linux (Debian package)
linux-aws (Ubuntu package)
linux-realtime-6.17 (Ubuntu package)
linux-gcp (Ubuntu package)
linux-raspi (Ubuntu package)

How to mitigate CVE-2025-71072

Install update from vendor's repository.

python3-perf-debuginfo - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
bpftool - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
bpftool-debuginfo - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-debuginfo - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-debugsource - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-devel - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-headers - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-tools - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-tools-debuginfo - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-tools-devel - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
perf - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
perf-debuginfo - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
python3-perf - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-source - addressed in versions 6.6.0-144.0.0.127, 6.6.0-144.0.0.139, 6.6.0-144.0.0.140
kernel-extra-modules - update to 6.6.0-144.0.0.140
linux (Ubuntu package) - addressed in versions 6.8.0-110.110, 6.8.0-110.110.1, 6.8.0-110.110.1~22.04.1, 6.8.0-1037.40, 6.8.0-1050.56, 6.8.0-1051.51, 6.8.0-1052.55~22.04.1, 6.8.0-1054.57, 6.17.0-22.22, 6.17.0-1010.11
linux-aws-fips (Ubuntu package) - addressed in versions 6.8.0-110.110+fips2, 6.8.0-1052.55+fips1, 6.8.0-1054.57+fips1
linux-hwe-6.8 (Ubuntu package) - addressed in versions 6.8.0-110.110~22.04.1, 6.8.0-1051.51~22.04.1, 6.8.0-1052.56
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1022.22
linux-xilinx (Ubuntu package) - update to 6.8.0-1029.30
linux-oracle (Ubuntu package) - addressed in versions 6.8.0-1049.50, 6.8.0-1049.50~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1051.54, 6.8.0-1051.54~22.04.1
linux-nvidia-lowlatency (Ubuntu package) - update to 6.8.0-1051.54.1
linux-gcp-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1054.60, 6.17.0-1013.13, 6.17.0-1013.13~24.04.1, 6.17.0-1020.20
linux-azure-fips (Ubuntu package) - update to 6.8.0-1054.60+fips1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2042.43
linux-realtime (Ubuntu package) - update to 6.8.1-1047.48
kernel (Red Hat package) - update to 6.12.0-211.46.1.el10_2
linux (Debian package) - update to 6.12.69-1
linux-aws (Ubuntu package) - addressed in versions 6.17.0-22.22~24.04.1, 6.17.0-1011.11, 6.17.0-1011.11~24.04.1, 6.17.0-1012.12, 6.17.0-1012.12~24.04.1
linux-realtime-6.17 (Ubuntu package) - update to 6.17.0-1010.11~24.04.1
linux-gcp (Ubuntu package) - addressed in versions 6.17.0-1012.12, 6.17.0-1012.12~24.04.1
linux-raspi (Ubuntu package) - update to 6.17.0-1014.14

External References

Related Security Bulletins